webrick
RubyGems6 known CVEs affecting this package
Aggregated from OSV, GitHub Security Advisories, NVD, and vendor advisories. Each CVE links to its full detail page with vendor advisories, patches, fixed versions, and remediation guidance.
CVEs affecting webrickpage 1 of 1
- CVE-2008-4310NONECVSS 0.0EG 0.0✓ Fixed in 1.3.12008-12-09
httputils.rb in WEBrick in Ruby 1.8.1 and 1.8.5, as used in Red Hat Enterprise Linux 4 and 5, allows remote attackers to cause a denial of service (CPU consumption) via a crafted HTTP request. NOTE: this issue exists because of an incompl…
- CVE-2009-4492NONECVSS 0.0EG 0.0✓ Fixed in 1.4.02010-01-13
vulnerable: 1.3.1, 1.4.0.beta1
WEBrick 1.3.1 in Ruby 1.8.6 through patchlevel 383, 1.8.7 through patchlevel 248, 1.8.8dev, 1.9.1 through patchlevel 376, and 1.9.2dev writes data to a log file without sanitizing non-printable characters, which might allow remote attacker…
- CVE-2017-10784HIGHCVSS 8.8EG 8.8✓ Fixed in 1.4.02017-09-19
vulnerable: 1.3.1, 1.4.0.beta1
The Basic authentication code in WEBrick library in Ruby before 2.2.8, 2.3.x before 2.3.5, and 2.4.x through 2.4.1 allows remote attackers to inject terminal emulator escape sequences into its log and possibly execute arbitrary commands vi…
- CVE-2020-25613HIGHCVSS 7.5EG 7.5✓ Fixed in 1.4.42020-10-06
vulnerable: 1.3.1 ... 1.4.3 (6 versions)
An issue was discovered in Ruby through 2.5.8, 2.6.x through 2.6.6, and 2.7.x through 2.7.1. WEBrick, a simple HTTP server bundled with Ruby, had not checked the transfer-encoding header value rigorously. An attacker may potentially exploi…
- CVE-2024-47220NONECVSS 0.0EG 0.0✓ Fixed in 1.8.22024-09-22
vulnerable: 1.3.1 ... 1.8.1 (14 versions)
An issue was discovered in the WEBrick toolkit through 1.8.1 for Ruby. It allows HTTP request smuggling by providing both a Content-Length header and a Transfer-Encoding header, e.g., "GET /admin HTTP/1.1\r\n" inside of a "POST /user HTTP/…
- CVE-2025-6442MEDIUMCVSS 5.9EG 5.9✓ Fixed in 1.8.22025-06-25
vulnerable: 1.3.1 ... 1.8.1 (14 versions)
Ruby WEBrick read_header HTTP Request Smuggling Vulnerability. This vulnerability allows remote attackers to smuggle arbitrary HTTP requests on affected installations of Ruby WEBrick. This issue is exploitable when the product is deployed …
Check whether webrick is used in your infrastructure
EchelonGraph scans your cloud and SBOMs to map every package to your actual deployments. See blast radius for webrick CVEs against the assets you own.
Start Free Scan →